A coordinated operation involving 131 Chrome extensions has been uncovered, with all extensions abusing WhatsApp Web to automate spam messaging at scale. These extensions, which are essentially rebrands of a single tool, share the same codebase, design patterns, and backend infrastructure, indicating a deliberate attempt to evade detection and maximize reach. The extensions inject code directly into the WhatsApp Web interface, running alongside legitimate scripts to automate bulk outreach and message scheduling. This activity is designed to bypass WhatsApp’s anti-spam mechanisms, enabling the operators to send unsolicited messages to large numbers of users. Marketing materials for these extensions falsely claim that their presence in the Chrome Web Store implies a rigorous security audit and full privacy compliance, misleading potential users and resellers. Contrary to these claims, the extensions violate both Chrome Web Store and WhatsApp policies by facilitating spam and unauthorized automation. At least 20,905 active users have been identified across the various extension listings, with some individual extensions, such as YouSeller, amassing over 10,000 users. The operation has been ongoing for at least nine months, with regular waves of new uploads and version updates observed throughout 2025, including as recently as mid-October. The extensions are marketed under different names, logos, and landing pages, but all provide the same WhatsApp Web automation interface, confirming their common origin. Security researchers have filed takedown requests with the Chrome security team and have called for the suspension of the associated publisher accounts. The Socket AI Scanner has flagged at least one extension, Organize-C, as malware due to its spamware behavior. The widespread availability of these extensions on the Chrome Web Store highlights significant gaps in extension vetting and enforcement. The operation’s scale and persistence suggest a lucrative reseller scheme, with the extensions being promoted as tools for mass outreach and marketing. The abuse of Chrome’s extension ecosystem for such purposes poses risks not only to WhatsApp users but also to the broader web platform. The incident underscores the need for improved monitoring and enforcement of extension policies by browser vendors. WhatsApp and Chrome users are advised to be vigilant about installing third-party extensions, especially those that promise automation or mass messaging capabilities. The exposure of this scheme may prompt further investigations into similar abuse patterns across other web platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.